CWE-269
Improper Privilege Management
Description
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-122 · CAPEC-233 · CAPEC-58
CVEs mapped to this weakness (3,702)
page 151 of 186| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-9490 | Med | 0.36 | 5.5 | 0.00 | May 25, 2026 | A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a specially crafted message (message type 0x03) to the pipe,… | ||
| CVE-2026-32212 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32181 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally. | ||
| CVE-2026-2640 | Med | 0.36 | 5.5 | 0.00 | Mar 11, 2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes. | ||
| CVE-2026-29122 | Med | 0.36 | 5.5 | 0.00 | Mar 5, 2026 | International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to… | ||
| CVE-2025-24183 | Med | 0.36 | 5.5 | 0.00 | May 19, 2025 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local user may be able to modify protected parts of the file system. | ||
| CVE-2023-32197 | Med | 0.36 | 6.6 | 0.01 | Apr 16, 2025 | A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=true is set can lead to privilege escalation in specific scenarios.This issue affects rancher: from 2.7.0 before 2.7.14, from 2.8.0 before 2.8.5. | ||
| CVE-2022-1804 | Med | 0.36 | 5.5 | 0.00 | Mar 25, 2025 | accountsservice no longer drops permissions when writting .pam_environment | ||
| CVE-2024-48828 | Med | 0.36 | 5.5 | 0.00 | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. | ||
| CVE-2025-25872 | Med | 0.36 | 5.5 | 0.00 | Mar 14, 2025 | An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function | ||
| CVE-2024-54560 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A malicious app may be able to modify other apps without having App Management permission. | ||
| CVE-2025-23007 | Med | 0.36 | 5.5 | 0.00 | Jan 30, 2025 | A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation. | ||
| CVE-2024-44147 | Med | 0.36 | 5.5 | 0.00 | Sep 17, 2024 | This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized access to Local Network. | ||
| CVE-2024-6326 | Med | 0.36 | 5.5 | 0.00 | Jul 16, 2024 | An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and… | ||
| CVE-2024-5909 | Med | 0.36 | 5.5 | 0.00 | Jun 12, 2024 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | ||
| CVE-2024-2431 | Med | 0.36 | 5.5 | 0.00 | Mar 13, 2024 | An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode. | ||
| CVE-2022-32931 | Med | 0.36 | 5.5 | 0.00 | Jan 10, 2024 | This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to access private information. | ||
| CVE-2023-5960 | Med | 0.36 | 5.5 | 0.00 | Nov 28, 2023 | An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system files on an affected device. | ||
| CVE-2023-5797 | Med | 0.36 | 5.5 | 0.00 | Nov 28, 2023 | An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware… | ||
| CVE-2023-5650 | Med | 0.36 | 5.5 | 0.00 | Nov 28, 2023 | An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16… |
- risk 0.36cvss 5.5epss 0.00
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a specially crafted message (message type 0x03) to the pipe,…
- risk 0.36cvss 5.5epss 0.00
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.
- risk 0.36cvss 5.5epss 0.00
International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to…
- risk 0.36cvss 5.5epss 0.00
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local user may be able to modify protected parts of the file system.
- risk 0.36cvss 6.6epss 0.01
A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=true is set can lead to privilege escalation in specific scenarios.This issue affects rancher: from 2.7.0 before 2.7.14, from 2.8.0 before 2.8.5.
- risk 0.36cvss 5.5epss 0.00
accountsservice no longer drops permissions when writting .pam_environment
- risk 0.36cvss 5.5epss 0.00
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
- risk 0.36cvss 5.5epss 0.00
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
- risk 0.36cvss 5.5epss 0.00
A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A malicious app may be able to modify other apps without having App Management permission.
- risk 0.36cvss 5.5epss 0.00
A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation.
- risk 0.36cvss 5.5epss 0.00
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized access to Local Network.
- risk 0.36cvss 5.5epss 0.00
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and…
- risk 0.36cvss 5.5epss 0.00
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
- risk 0.36cvss 5.5epss 0.00
An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.
- risk 0.36cvss 5.5epss 0.00
This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to access private information.
- risk 0.36cvss 5.5epss 0.00
An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system files on an affected device.
- risk 0.36cvss 5.5epss 0.00
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware…
- risk 0.36cvss 5.5epss 0.00
An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16…